Sql Best Practices

作者 mindrally97184105b5da無授權條款269 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫5 週前更新

SQL development best practices for writing efficient, secure, and maintainable database queries

AI 產生的概覽

撰寫高效、安全且易於維護的 SQL 查詢與資料庫程式碼的準則。

功能
提供 SQL 開發最佳實務參考,涵蓋查詢格式、欄位選取、篩選條件、聯結、索引、查詢最佳化、彙總、交易、安全性、資料異動、命名慣例、文件與錯誤處理。每個領域都包含規則與範例 SQL。它產出的是指引建議,而非可執行的成品。
適用情境
適用於撰寫、審查或統一 SQL 查詢與資料庫程式碼的情境。適合希望讓資料庫工作在風格、效能與安全慣例上保持一致的團隊。
執行需求
不需要任何工具、套件或憑證;僅為說明性內容,不附帶指令碼。

SQL Best Practices

Core Principles

  • Write clear, readable SQL with consistent formatting and meaningful aliases
  • Prioritize query performance through proper indexing and optimization
  • Implement security best practices to prevent SQL injection
  • Use transactions appropriately for data integrity
  • Document complex queries with inline comments

Query Writing Standards

Formatting and Style

  • Use uppercase for SQL keywords (SELECT, FROM, WHERE, JOIN)
  • Place each major clause on a new line for readability
  • Use meaningful table aliases (e.g., customers AS c not customers AS x)
  • Indent subqueries and nested conditions consistently
  • Align column lists and conditions for visual clarity
sql
SELECT    c.customer_id,    c.customer_name,    o.order_date,    o.total_amountFROM customers AS cINNER JOIN orders AS o ON c.customer_id = o.customer_idWHERE o.order_date >= '2024-01-01'    AND o.status = 'completed'ORDER BY o.order_date DESC;

Column Selection

  • Avoid SELECT * in production code; explicitly list required columns
  • Use column aliases to clarify output: SELECT first_name AS "First Name"
  • Consider the order of columns in SELECT for logical grouping

Filtering and Conditions

  • Place most restrictive conditions first in WHERE clauses
  • Use appropriate operators: prefer IN over multiple OR conditions
  • Use EXISTS instead of IN for subqueries when checking existence
  • Avoid functions on indexed columns in WHERE clauses when possible
  • Use parameterized queries to prevent SQL injection
sql
-- Preferred: Use EXISTS for existence checksSELECT c.customer_nameFROM customers AS cWHERE EXISTS (    SELECT 1 FROM orders AS o    WHERE o.customer_id = c.customer_id    AND o.order_date > '2024-01-01');
-- Avoid: Function on indexed columnWHERE YEAR(order_date) = 2024
-- Preferred: Range comparisonWHERE order_date >= '2024-01-01' AND order_date < '2025-01-01'

Join Best Practices

  • Always use explicit JOIN syntax instead of implicit joins in WHERE
  • Specify join type explicitly (INNER, LEFT, RIGHT, FULL OUTER)
  • Order joins from largest to smallest table when possible
  • Use appropriate join types based on data requirements
  • Be cautious with CROSS JOINs; ensure they are intentional
sql
-- Explicit join (preferred)SELECT c.name, o.order_idFROM customers AS cINNER JOIN orders AS o ON c.customer_id = o.customer_id;
-- Avoid implicit joinSELECT c.name, o.order_idFROM customers c, orders oWHERE c.customer_id = o.customer_id;

Performance Optimization

Indexing Guidelines

  • Create indexes on columns used in WHERE, JOIN, and ORDER BY clauses
  • Consider composite indexes for multi-column queries
  • Avoid over-indexing; each index adds write overhead
  • Regularly analyze and maintain indexes
  • Use covering indexes for frequently executed queries

Query Optimization

  • Use EXPLAIN/EXPLAIN ANALYZE to understand query execution plans
  • Limit result sets with TOP/LIMIT when full results are not needed
  • Use pagination for large result sets
  • Avoid correlated subqueries when possible; use JOINs instead
  • Consider query caching for frequently executed queries
sql
-- Pagination exampleSELECT product_id, product_name, priceFROM productsORDER BY product_idLIMIT 20 OFFSET 40;

Aggregation Best Practices

  • Filter before grouping when possible (WHERE vs HAVING)
  • Use appropriate aggregate functions (COUNT, SUM, AVG, etc.)
  • Consider window functions for running totals and rankings
sql
-- Efficient: Filter before aggregationSELECT category_id, COUNT(*) AS product_countFROM productsWHERE active = trueGROUP BY category_idHAVING COUNT(*) > 10;

Transaction Management

  • Keep transactions as short as possible
  • Use appropriate isolation levels for your use case
  • Always include error handling with ROLLBACK
  • Avoid user interaction during open transactions
  • Use savepoints for complex multi-step operations
sql
BEGIN TRANSACTION;
UPDATE accounts SET balance = balance - 100 WHERE account_id = 1;UPDATE accounts SET balance = balance + 100 WHERE account_id = 2;
IF @@ERROR <> 0    ROLLBACK TRANSACTION;ELSE    COMMIT TRANSACTION;

Security Best Practices

  • Always use parameterized queries or prepared statements
  • Never concatenate user input directly into SQL strings
  • Apply principle of least privilege for database users
  • Audit and log sensitive data access
  • Encrypt sensitive data at rest and in transit
sql
-- Use parameterized queries (pseudo-code)PREPARE stmt FROM 'SELECT * FROM users WHERE username = ?';EXECUTE stmt USING @username;

Data Modification Best Practices

INSERT Operations

  • Always specify column names explicitly
  • Use bulk inserts for multiple rows when possible
  • Consider using MERGE/UPSERT for insert-or-update scenarios
sql
INSERT INTO customers (customer_name, email, created_at)VALUES    ('John Doe', '[email protected]', CURRENT_TIMESTAMP),    ('Jane Smith', '[email protected]', CURRENT_TIMESTAMP);

UPDATE Operations

  • Always include a WHERE clause (unless intentionally updating all rows)
  • Test UPDATE queries with SELECT first
  • Consider using transactions for critical updates

DELETE Operations

  • Always include a WHERE clause
  • Use soft deletes (status flags) for recoverable data
  • Consider CASCADE effects on related tables

Naming Conventions

  • Use snake_case for table and column names
  • Use singular nouns for table names (customer, not customers)
  • Prefix primary keys with table name: customer_id
  • Use descriptive names: order_total not ot
  • Prefix boolean columns appropriately: is_active, has_shipped

Documentation

  • Comment complex business logic within queries
  • Document stored procedures with purpose, parameters, and examples
  • Maintain a data dictionary for table and column descriptions
  • Version control database schema changes

Error Handling

  • Implement proper error handling in stored procedures
  • Log errors with sufficient context for debugging
  • Return meaningful error messages to calling applications
  • Use TRY-CATCH blocks where supported

來源與署名

來源:mindrally/skills位於sql-best-practices提交9718410

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架